Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-61866

Опубликовано: 15 июл. 2026
Источник: redhat
CVSS3: 2.9

Описание

ImageMagick before 7.1.2-26 contains a memory leak vulnerability in the JNG encoder when a blob cannot be opened. Attackers can trigger the memory leak by providing malformed JNG files that fail blob operations, causing resource exhaustion.

A flaw was found in ImageMagick. A memory leak vulnerability exists in the JNG (JPEG Network Graphics) encoder when the application fails to open a blob. A remote attacker could exploit this by providing specially crafted malformed JNG files, leading to resource exhaustion and a denial of service (DoS) for the affected system.

Отчет

Red Hat Enterprise Linux ships ImageMagick in RHEL 6 ELS and RHEL 7 ELS. This flaw has been rated as having a Low security impact and is not currently planned to be addressed in future updates of those products. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.

Меры по смягчению последствий

Do not process untrusted image files with ImageMagick. The JNG coder can be disabled in ImageMagick's policy.xml if not needed: <policy domain="coder" rights="none" pattern="JNG"/>. Upgrade to ImageMagick 7.1.2-26 or 6.9.13-51 mitigates the issue.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6ImageMagickFix deferred
Red Hat Enterprise Linux 7ImageMagickFix deferred

Показывать по

Дополнительная информация

Статус:

Low
Дефект:
CWE-772
https://bugzilla.redhat.com/show_bug.cgi?id=2500926ImageMagick: ImageMagick: Memory leak in JNG encoder can lead to denial of service

2.9 Low

CVSS3

Связанные уязвимости

CVSS3: 2.9
ubuntu
19 дней назад

ImageMagick before 7.1.2-26 contains a memory leak vulnerability in the JNG encoder when a blob cannot be opened. Attackers can trigger the memory leak by providing malformed JNG files that fail blob operations, causing resource exhaustion.

CVSS3: 2.9
nvd
19 дней назад

ImageMagick before 7.1.2-26 contains a memory leak vulnerability in the JNG encoder when a blob cannot be opened. Attackers can trigger the memory leak by providing malformed JNG files that fail blob operations, causing resource exhaustion.

CVSS3: 2.9
debian
19 дней назад

ImageMagick before 7.1.2-26 contains a memory leak vulnerability in th ...

CVSS3: 2.9
github
19 дней назад

ImageMagick before 7.1.2-26 contains a memory leak vulnerability in the JNG encoder when a blob cannot be opened. Attackers can trigger the memory leak by providing malformed JNG files that fail blob operations, causing resource exhaustion.

suse-cvrf
12 дней назад

Security update for ImageMagick

2.9 Low

CVSS3